PT-2026-51811 · Jenkins · Owasp Zap Plugin

CVE-2026-57301

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins OWASP ZAP Plugin versions prior to 1.0.8
Description Build operations are performed on the Jenkins controller instead of the assigned agent. This allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
Recommendations Update Jenkins OWASP ZAP Plugin to version 1.0.8 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57301

Affected Products

Owasp Zap Plugin